Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.332GitHub PoC 14.209VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
Claroline 1.8.3 - '$_SERVER['PHP_SELF']' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Instant Support - Driver Check Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check be
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Liesbeth Base CMS - Information Disclosure
Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Moodle 1.7.1 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Yoggie Pico and Pico Pro Backticks - Remote Code Execution
Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPDirector 0.21 - 'videos.php?id' SQL Injection
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPDirector 0.21 - 'videos.php?id' SQL Injection
PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Rapid Install Web Server - Secondary Login Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PC SOFT WinDEV 11 - '.WDP' File Parsing Stack Buffer Overflow
Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ETicket 1.5.5 - 'Open.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer/HelixPlayer - SMIL wallclock Stack Overflow (PoC)
Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPla
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Conti FTP Server 1.0 - Large String Denial of Service
Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys WAG54GS 1.0.6 (Wireless-G ADSL Gateway) - 'setup.cgi' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway wi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GD Graphics Library 2.0.34 - 'libgd' gdImageCreateXbm Function Unspecified Denial of Service
The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
6ALBlog - 'newsid' SQL Injection
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the m
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Key Focus Web Server 3.1 - Index.WKF Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebCT 4.1.5 - Email and Discussion Board Messages HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SHTTPD 1.38 - Filename Parse Error Information Disclosure
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari 3.0.x for Windows - 'Document.Location.Hash' Buffer Overflow
Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Calendarix 0.7.20070307 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LiteWEB Web Server 2.7 - Invalid Page Remote Denial of Service
LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent p
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Calendarix 0.7.20070307 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MyNews 0.10 - AuthACC SQL Injection
SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eNdonesia 8.4 - 'mod.php?viewarticle Action artid' SQL Injection
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eNdonesia 8.4 - 'banners.php?click Action bid' SQL Injection
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebCore - XMLHTTPRequest Cross-Site Scripting
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetClassifieds - SQL Injection / Cross-Site Scripting / Full Path
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BugHunter HTTP Server 1.6.2 - 'httpsv.exe' GET 404 Remote Denial of Service
BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPAccounts 0.5 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local fil
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ingress Database Server 2.6 - Multiple Remote Vulnerabilities
Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe)
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.